I was testing Splunk App for *nix before putting it into production. We were consistently getting 30-40Mb/day, but while I was out of the office (14 days), the usage went over the 500Mb limit. I'm trying to determine what caused the overage and by how much before moving to production and having even bigger problems if we go over our 10Gb license.
Apps > Search > Status > Index Activity > Indexing
is displaying less than 100Mb per day.